Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7711

Опубликовано: 14 авг. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

Отчет

Whilst the OpenShift Container Platform (OCP) and OpenShift Service Mesh (OSSM) grafana container does include goxmldsig, it is only included as part of the SAML implementation. SAML is only available in the enterprise version of Grafana (https://grafana.com/docs/grafana/latest/auth/saml/). Hence the openshift4/ose-grafana and servicemesh-grafana containers have been marked as wont-fix and may be addressed in a future update.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-grafanaWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1871691goxmldsig: sending malformed XML signatures could result in a crash

EPSS

Процентиль: 77%
0.01769
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

CVSS3: 7.5
nvd
около 6 лет назад

This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

CVSS3: 7.5
debian
около 6 лет назад

This affects all versions of package github.com/russellhaering/goxmlds ...

CVSS3: 7.5
github
почти 4 года назад

goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures

EPSS

Процентиль: 77%
0.01769
Низкий

7.5 High

CVSS3